ensure all conn.log entries are tagged "ics" for OT protocols #541
Labels
enhancement
New feature or request
ics
Relating to ICS (Industrial Control Systems) devices
logstash
Relating to Malcolm's use of Logstash
zeek
Relating to Malcolm's use of Zeek
Milestone
We need to make sure that all conn.log entries get tagged with
ics
when an ICS protocol is detected.This is maybe already supposed to be handled but I don't see it is being done in every case. I wonder if it's actually an issue in the parsers. Some of them seem to be setting the service correctly (bacnet, s7comm) but I don't think that all of them.
So here's what needs to happen:
service
to the protocol name; if not, this will have to be submitted as a PR to that repositoryics
value into thetags
fieldThe text was updated successfully, but these errors were encountered: